Is there an idiots guide to deploying certificate-based pre-logon for Global protect?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

Is there an idiots guide to deploying certificate-based pre-logon for Global protect?

L4 Transporter

Folks.

As the subject requests, is there an "idiots guide" to deploying certificate-based pre-login for Global Protect?

My boss wants me to implement it so that pc's which are VPN-only connected can run domain scripts (machine policies) which only run on login - but you obviously don't connect to the domain until *after* you've logged in locally to the PC in the case of a VPN connected client - which means we need to have the PC connected to the VPN *before* login, so it can run scripts when the user actually logs in.

I've looked through the docs a bit, but can;t get my head around a few things - mainly, how you create and deploy the certificates which the PC's use to verify/connect to the firewall before the user logs in and supplies actual credentials to Global Protect.

Any pointers appreciated.

Thanks.

1 accepted solution

Accepted Solutions

L6 Presenter

this didn't help? if not, create a case after you're initial config and we can assist further

How To Configure GlobalProtect SSO With Pre-Logon Access Using Self-Signed Certificates

View solution in original post

4 REPLIES 4

L6 Presenter

this didn't help? if not, create a case after you're initial config and we can assist further

How To Configure GlobalProtect SSO With Pre-Logon Access Using Self-Signed Certificates

L7 Applicator

darren.g wrote:

mainly, how you create and deploy the certificates which the PC's use to verify/connect to the firewall before the user logs in and supplies actual credentials to Global Protect.

For certificate authentication on a windows domain you can use group policy to automatically create the certificates and auto enroll the domain computers. 

Configure Group Policy to Autoenroll and Deploy Certificates

With windows GINA pre login you essentially connect the login process on the computer to the creation of the vpn connection at login time.  This way you do get the benefits of on network login from the vpn connected computers.

Steve Puluka BSEET - IP Architect - DQE Communications (Metro Ethernet/ISP)
ACE PanOS 6; ACE PanOS 7; ASE 3.0; PSE 7.0 Foundations & Associate in Platform; Cyber Security; Data Center

nato wrote:

this didn't help? if not, create a case after you're initial config and we can assist further

How To Configure GlobalProtect SSO With Pre-Logon Access Using Self-Signed Certificates

That wasn't the doc I found and was referring to - but it looks like the doc I need!

Thanks!

No prob. If you get stuck, please open a case so we can rectify issue.

  • 1 accepted solution
  • 3392 Views
  • 4 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!